Drinking water and wastewater utilities in at least seven states, including Minnesota and Michigan, have been hit by cyberattacks in recent weeks, with suspicion falling on actors linked to Iran. Pennsylvania officials say the Commonwealth’s systems have so far been untouched, but they are not treating that as a reason to relax, according to WESA reporting from August 5.
The Pennsylvania Department of Environmental Protection and State Police both confirmed that no credible threats have been identified in the state. DEP spokesperson Neil Shader said the agency alerted drinking water and wastewater systems on July 22 about the breaches elsewhere, and DEP is working with a statewide response network that includes multiple water sector organizations. State Police say their units monitor threats around the clock and encourage operators to report suspicious activity to local police. None of the out of state attacks made water unsafe to drink.
The guidance for municipal systems is basic but urgent: restrict public internet access to operational controls and update passwords. Our region knows this threat firsthand. In 2023, an Iranian backed group hacked equipment at the Municipal Water Authority of Aliquippa in Beaver County, forcing operators to run part of the system manually and putting small utility cybersecurity on the national agenda.
Small rural systems are often the most exposed because they have the least IT capacity. If your watershed group works alongside a small municipal authority, this is a good week to forward the DEP guidance and ask whether anyone has checked which controls are reachable from the open internet.
Key details
- At least seven states affected; no attacks confirmed in Pennsylvania
- DEP alerted water and wastewater systems on July 22
- Recommended steps: restrict public internet access to controls, update passwords
- Regional context: 2023 hack of the Aliquippa water authority in Beaver County
Read more at 90.5 WESA, the source for this item.